[Legal] — Privacy Policy

Privacy Policy.
What we collect, why, and how we treat it.

Last updated
24 July 2026

Who we are

Soaringwebs Pty Ltd ("we", "us", "our") is an Australian web design and digital marketing studio. We operate from a private home business in Queensland and serve clients Australia-wide. This policy explains how we handle personal information when you visit soaringwebs.com, enquire, subscribe, use a client portal, connect a business account, or work with us.

If you have questions about this policy or how we handle your data, contact us at [email protected].

What we collect

Enquiry and subscription details — your name, email, phone number, business, website, service interests, budget range, timing, goals, notes and newsletter choice.

Client and onboarding details — business and contact details, ABN, service locations, brand materials, project requirements, decision-makers, account-access descriptions and the permissions you choose to provide. Do not put passwords, API keys or other secrets into free-text forms.

Portal and payment evidence — proposal or package details, onboarding responses, payment status and limited Stripe transaction references. Stripe processes card details; Soaringwebs does not receive or store your full card number.

Website and attribution data — page paths, referrer, browser or device information, IP address and country on some forms, session identifiers, form/call/booking actions, and campaign parameters such as UTM values or advertising click IDs.

Connected-platform details — if you deliberately use our Meta onboarding tools, we may process the account, Page, Instagram, permission and readiness information needed to perform the checks you requested.

We aim to collect only what is reasonably needed for the relevant enquiry, service, security check or measurement purpose.

How we collect information

We collect information directly when you submit a form, subscribe, email or call us, use a secure client link, complete onboarding, connect an account or otherwise provide it during a client relationship.

We also collect limited technical and usage information through our hosting, security, analytics and first-party conversion systems. Information may be linked to an enquiry or client record where needed to understand its source and outcome.

Why we use information

To respond to enquiries, provide audits, prepare proposals, deliver and support agreed services, manage onboarding and verify payments.

To send service-related confirmations and messages, keep client-specific records, measure qualified and won outcomes, and prevent one client’s data being mixed with another’s.

To operate, secure and improve the website, understand which content and campaigns lead to genuine enquiries, diagnose faults, prevent abuse and maintain audit records.

To meet legal, accounting, dispute-resolution and regulatory obligations.

Analytics, storage and advertising measurement

Marketing pages currently use Cloudflare Web Analytics and Google Analytics 4. These services may process technical, device, page, referrer and approximate-location information. Private deal-portal pages are configured not to load those marketing analytics scripts.

Our first-party Chester tracker may record form submissions, phone-link clicks and booking actions together with a session identifier, page, referrer and campaign/click parameters. It stores conversion records for up to 90 days and does not intentionally store the visitor’s raw IP address in that conversion record.

The site uses browser session storage for privacy-minimised session and first-touch attribution information. Secure portals and onboarding tools may use signed session cookies required for authentication and security.

We do not currently deploy a Meta advertising pixel through this website source. If we later enable Meta or another third-party advertising pixel, we will update the relevant collection notice and opt-out controls before using it.

Lead assessment and AI assistance

Website enquiries may receive an automated internal priority score using details such as whether a business name, phone, budget, timeline or website was supplied and whether a submission appears automated. This helps us order follow-up; it does not by itself accept or reject a client, set a price or make a legally significant decision.

Chester and approved AI tools may assist with analysis or drafting for an agreed service. We do not automatically send website form submissions to a generative AI provider. If AI-assisted processing of client material is proposed, we limit it to what is necessary, follow the client’s instructions and apply the relevant provider and confidentiality safeguards.

Email, SMS and direct marketing

Submitting an enquiry allows us to respond about that enquiry and send a related confirmation. It does not automatically subscribe you to unrelated marketing.

We send newsletters or other commercial email/SMS only where we have the required express or inferred consent. Commercial messages identify Soaringwebs and provide a working unsubscribe or opt-out method.

You can unsubscribe through the link or instructions in a message, reply STOP to an enabled marketing SMS route, or email us. We keep a suppression record so the opt-out continues to be honoured.

Who we share information with

We do not sell personal information or client leads.

We disclose only what is reasonably needed to service providers involved in hosting and storage (Cloudflare), analytics (Google), transactional email (Resend and our business mail provider), optional phone notifications (ntfy or a replacement we approve), booking, payment processing (Stripe), and connected platforms such as Meta when you deliberately authorise that connection.

Client information may also be handled in Chester’s client-scoped business systems and by professional advisers, contractors or approved AI providers where needed for the agreed service and subject to appropriate access and confidentiality controls.

We may disclose information where required by law, to protect people or systems, or to establish, exercise or defend legal rights.

Overseas processing

Soaringwebs operates in Australia, but some providers may process or store information in the United States and other countries where they or their subprocessors operate. Privacy protections and laws can differ between countries.

We select providers and access settings with the aim of limiting information to what is necessary. Contact us if you want more detail about the providers relevant to your record.

How long we keep information

Temporary instant-audit records are designed to expire after about 30 minutes. First-party conversion records expire after about 90 days.

Website lead records are designed to expire after about 12 months. General onboarding records may be kept for up to two years. Secure portal onboarding, payment-verification and revocation records are generally kept for up to 12 months, while portal activity events are generally kept for up to 90 days.

Newsletter records remain until you unsubscribe or ask for deletion; an opt-out suppression record may be retained so we do not contact you again.

Active-client, transaction, accounting, dispute and legal records may be kept longer where reasonably necessary or legally required. When information is no longer needed, we take reasonable steps to delete it or remove identifying details.

Security

We use access controls, client scoping, encrypted connections, limited retention, signed portal links, rate limits and audit records appropriate to the information and service.

No online system can be guaranteed completely secure. If you believe information has been exposed or a secure link has reached the wrong person, contact us promptly so we can contain and investigate it.

Access, correction and deletion

You can ask what personal information we hold about you, request access or correction, withdraw a marketing consent, or request deletion where we are not required to keep the information. Email [email protected] with enough detail for us to verify and action the request.

We aim to respond within 30 days. We may need to verify your identity and may be unable to delete information that must be retained for legal, accounting, security or dispute purposes.

Privacy complaints

Email [email protected] with “Privacy complaint” in the subject and explain what happened. We will acknowledge the complaint, investigate it and explain our response, normally within 30 days.

If you remain dissatisfied and the Privacy Act applies to the matter, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

We review this policy when our website, providers or information-handling practices change. The “last updated” date at the top records the latest revision.